Automated ransomware attack exploited Langflow CVE-2025-3248 and Nacos CVE-2021-29441 to destroy server data

Researchers say an attacker used a large language model to automate a full ransomware and extortion attack against exposed servers, ending with encrypted and deleted data. Sysdig said the intrusion began by exploiting Langflow CVE-2025-3248, an unauthenticated remote-code-execution flaw, then moved to a production server running MySQL and Alibaba Nacos, abused Nacos CVE-2021-29441 and the product's default JWT signing key, added a backdoor admin, and encrypted 1,342 configuration records before dropping database schemas.
Why it matters: Organizations running internet-exposed Langflow or Nacos instances could face fast, destructive break-ins that do not reliably allow recovery even if a ransom is paid. Defenders should urgently patch or isolate exposed systems, rotate credentials, and check for cron-based persistence, rogue Nacos admins, and database tampering.

Sources

JadePuffer ransomware used AI agent to automate entire attack
Bill Toulas 2026.07.04 97% relevant
This appears to be the same underlying JadePuffer incident and adds specific attribution of the intrusion workflow to an autonomous LLM agent, along with concrete details on post-exploitation behavior: PostgreSQL dumping, MinIO enumeration, cron-based persistence, pivoting to Nacos, and encryption of 1,342 configuration items using MySQL AES_ENCRYPT().
Agentic AI Used to Conduct Ransomware Attack via Langflow
Ionut Arghire 2026.07.03 99% relevant
This is a direct update on the same underlying event: a ransomware attack in which attackers exploited Langflow CVE-2025-3248, pivoted to Nacos using CVE-2021-29441 and the default JWT signing key, and used an LLM agent to automate reconnaissance, credential theft, lateral movement, persistence, and destructive encryption.
Smooth AI criminal drives 'first' end-to-end agentic ransomware attack
2026.07.02 100% relevant
This article establishes a distinct incident centered on an automated ransomware intrusion that chained Langflow CVE-2025-3248 with Nacos weaknesses to encrypt and destroy production data.
← Back to all stories